Vendor
high
advisory
Privilege Escalation in uutils coreutils via Incorrect File Ownership Handling
1 TTP 1 CVEuutils coreutils versions before 0.10.0 are vulnerable to local privilege escalation due to an race condition in the install utility that preserves setuid/setgid bits when ownership changes fail.
coreutils
vulnerability
privilege-escalation
linux
1t
1c
high
threat
mkfifo: permissions of an existing file are changed after FIFO creation fails
3 TTPs 1 CVEA vulnerability (CVE-2026-35341) exists in the `uu_mkfifo` utility of `uutils coreutils`, affecting versions prior to 0.6.0. When `mkfifo()` fails because the target file already exists, the utility incorrectly proceeds to modify the permissions of the pre-existing file to `0644`. This can inadvertently relax permissions on sensitive owner-only files, such as SSH private keys, making them accessible to other users on the system and potentially enabling unauthorized access or information disclosure. The issue has been patched in PR #10376.
exploited
uu_mkfifo +1
vulnerability
linux
coreutils
permissions
information-disclosure
privilege-escalation
3t
1c